Jump to content

Recommended Posts

Posted

Sometimes we can have a lot of supply staff in. Currently we have supply1, supply2, supply3 that is given out by the cover person. With this account they can login to the network as a normal teacher, access teacher shares and youtube/internet.

 

How do you guys manage supply requirements?

Posted
Our supply accounts don't have access to our shares (relevant work is passed on USB pens) - the account has access to the internet and the standard office apps (and some other bits of software) but not much else.
  • Thanks 1
Posted
We do exactly the same as you Mark, but they don't have access to SIMS; they use paper registers. Password changed for each issue, of course. Long term supply (e.g. illness, maternity etc) have "proper" accounts.
  • Thanks 1
Posted
Our cover accounts are normal staff accounts. The only difference is that they cannot access sharepoint
@witch does this not open up issues in terms of Safeguarding (and subsequently GDPR) with access to files that may contain confidential data?
  • Thanks 1
Posted
Here we compromise on that; although our supply staff don't have SIMS access they do have access to some confidential data via our intranet, e.g. basic SEN, PPI details etc - they need this to do an effective job.
  • Thanks 1
Posted

Supply teachers log in as "supply" which is permitted to be used on a couple of machines at any one time.

Work experience students log in as "visitor".

 

Both accounts have staff Internet filtering but are blocked from accessing the staff shared area, SIMS or target tracker.

Teachers are reminded to put planning under the children's shared area in the relevant subject folder so these users can access them.

  • Thanks 1
Posted
Supply accounts are essentially staff accounts but without all the mapped drives - just the planning and student work shares. No Office365 access, no MIS and they have remote sign-ins revoked. password changed weekly.
  • Thanks 1
Posted
@witch does this not open up issues in terms of Safeguarding (and subsequently GDPR) with access to files that may contain confidential data?

 

 

Yes

Have I mentioned it

Yes

Has anything been done

No

 

 

That is all

  • Thanks 4
Posted (edited)

Each supply has their own account for accountability reasons. Personally I don't agree with shared accounts even though only one person will be accessing it at anyone time, the control is taken out of my hands.

Network Accounts are only active on the days the user is in.

No mis.

email access is provided.

Access to staff shares are prohibited.

redirected Supply share which is a folder in within the staff share where staff upload work to equip the covering teacher to do his or her job.

 

EDIT

All remote services are prohibited

Account is deleted after at least one year of inactive duty

 

There are some exceptions for long term supply (mat cover etc) where their privileges can be increased if required and approved by SLT upto a normal staff account

Edited by dapaulio
  • Thanks 1
Posted
Each supply has their own account for accountability reasons. Personally I don't agree with shared accounts even though only one person will be accessing it at anyone time, the control is taken out of my hands.

Network Accounts are only active on the days the user is in.

No mis.

email access is provided.

Access to staff shares are prohibited.

redirected Supply share which is a folder in within the staff share where staff upload work to equip the covering teacher to do his or her job.

 

So - you have to set up a whole new account every time a different supply teacher is used? Seems like a lot of work

  • Thanks 2
Posted
So - you have to set up a whole new account every time a different supply teacher is used? Seems like a lot of work

 

It may seem strict but not really very time consuming as they have no privileges really to set. my user accounts are script generated. Stick their first name, surname, username in a txt file and run 2 scripts. less than a minutes work.

 

Staff and student accounts take me longer as they are registered on O365, SLG, sims, remote access etc. I have to wait at least 30 mins for O365 to sync so I can allocated a license to the user

  • Thanks 1
Posted
So - you have to set up a whole new account every time a different supply teacher is used? Seems like a lot of work

 

 

I have to agree with that. We can sometimes have 5/6 staff phoning in at 7:30 saying they wont be in. Yes we have cover supervisors but not that many to have to get supply staff in.

Posted
We have the username and password for the supply 1-10 accounts on cards in the office. They hand these out and get them returned when staff leave at the end of the day with their lanyard. They have no email access etc.
  • Thanks 1
Posted

In the schools i look after, we have a spare laptops pre-configured with all the software they need on, only access to school share for pupils and staff on mapped drive.

Normal class teacher leaves a list of work that the children need to cover.

Supply are given a temp login for registration on school MIS which is cloud based or use a printed sheet that is completed and sent to the office.

  • 1 month later...
Posted

I've just been reading over everyone's comments on this and was wondering if you deal with trainee teachers in the same way as supply teachers?

 

We are just in the process of changing the way we set up or Supply accounts to almost mirror what Dapolio has suggested and Im thinking the same should apply to trainee teachers also?

Posted
I've just been reading over everyone's comments on this and was wondering if you deal with trainee teachers in the same way as supply teachers?

 

We are just in the process of changing the way we set up or Supply accounts to almost mirror what Dapolio has suggested and Im thinking the same should apply to trainee teachers also?

 

Yes I employ the same protocol for trainees. They have full staff privileges with the only difference is their account have an expiration date of their contract end date. If one is not provided on request I set the account to expire at the end of the current terms holiday. If they then return the next term they have to come and see me to extend their account.

This gives me the opportunity to meet and talk to them (see if they are fit etc) and extend their account by an appropriate amount of time

  • Thanks 2
Posted (edited)

What we are talking about is identity management, I would say that having a shared account no matter how restrictive is not cutting it for auditing and accountability reasons unless you are keeping a detailed log of the actual soft mushy bit (the individual) that is being given the shared account details and in that log the times and dates that those have had access to the account. If you are then surly its easier to create an account?

 

On that note it would be wise to use identity types, so have a identity of supply teacher/ work experience/ staff..... and then have groups, leverage the power of AD and scripts to manage what access is granted to those identities indeed a lot of the leg work for managing access should be based on what is in your golden sources for Staff/ Student/ Externals data, the lion share of your groups can be built and based on whats in your HR/ Staff solutions. Then all you are doing as IT is assigning the correct permissions to those groups. If you are using cloudy based offerings from MS you can filter out users/ groups that should not be synced to your tenant but you could also allow the sync and use other methods of applying the required license for the services an identity type should have access to (a script can do this, do not sit in front of the portal assigning licenses to your users!)

 

Anyhow I can talk identity management and the whole life cycle for an identity all day long.

Edited by HPlum78
Posted
We give a generic Supply account out, that has Staff level access but no access to Staff shares. So they can open applications and use the internet - if they need specific resources they are copied into their profile. We also give Trainee teachers their own account and email as they're usually here for a decent while
  • Thanks 1
Posted

So we currently give full access to supply and trainee teachers to access all shares and MIS systems.

 

I am trying to change this as it is clearly a data breach waiting to happen?

 

Am I wrong?

 

As the head has just asked me is this linked to security and why would we stop supply staff from accessing MIS systems, why are these staff more unreliable than than any other staff?

 

I’m struggling to see how this is not obvious or am I missing something here?

Posted (edited)
So we currently give full access to supply and trainee teachers to access all shares and MIS systems.

 

I am trying to change this as it is clearly a data breach waiting to happen?

 

Am I wrong?

 

This is just my opinion, but, yes, I think you're mainly right.

 

Both supply and trainees are working legitimately for your organisation, are expected to uphold the same values and confidentiality as a full-time teacher and have a need to access the same sort of data as them. So long as supply and trainees are instructed to follow your organisation's policies on data protection and if necessary given training on how to access data securely then all is well in GDPR land.

 

If you don't allow trainee teachers to access things like your MIS, tracking data or other such things then they are not getting the full picture of what it means to be a teacher and the confidential nature of much of what they do.

 

Similarly with supply teachers; if they can't access student data then they can't deliver cover lessons that rely on any of that data unless someone else prints it out for them (e.g. setting appropriate work targeted at a student's ability level.)

 

Now the level of detail you give people access to is up for debate of course. Nobody except a head/principal, business manager and HR should have access to staff salary and contract details for example but at the other end of the scale, pretty much the whole school staff will need to be able to discover that Jimmy Smith in 9K is allergic to bee stings and carries an Epi pen.

Edited by KevinB
Posted (edited)

i use a modified script i found on this site to send 10 guest login details to the office every day which are reset every day and resent which can be used for the staff wifi and staff use of the computers/printers minus the mapped drives and planning for the day is provided on paper i think

 

Scholarpack has guest logins that it can spit out for a days basic use

Edited by DGardiner
Posted
This is just my opinion, but, yes, I think you're mainly right.

 

Both supply and trainees are working legitimately for your organisation, are expected to uphold the same values and confidentiality as a full-time teacher and have a need to access the same sort of data as them. So long as supply and trainees are instructed to follow your organisation's policies on data protection and if necessary given training on how to access data securely then all is well in GDPR land.

 

If you don't allow trainee teachers to access things like your MIS, tracking data or other such things then they are not getting the full picture of what it means to be a teacher and the confidential nature of much of what they do.

 

Similarly with supply teachers; if they can't access student data then they can't deliver cover lessons that rely on any of that data unless someone else prints it out for them (e.g. setting appropriate work targeted at a student's ability level.)

 

Now the level of detail you give people access to is up for debate of course. Nobody except a head/principal, business manager and HR should have access to staff salary and contract details for example but at the other end of the scale, pretty much the whole school staff will need to be able to discover that Jimmy Smith in 9K is allergic to bee stings and carries an Epi pen.

 

Thanks for your input KevinB

 

But that seems to go against this thread altogether.

 

Why for instance are so many not allowing access to MIS systems/ shares etc if this is not a problem?

 

Just wondering [emoji849]

Posted
We give supply teachers access to the staff shares and a limited MIS login (enough to do their job as supply teacher i.e. access to registration). Trainee teachers get less as we don't have a contract (i.e. contract of employment or contract with the supply agency) with them, although if the head of department of whatever subject they are training in asks for them to have access to the staff share we give it out. Neither are allocated email except for long term supply teachers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...